Skip to content

Latest commit

 

History

3 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Suricata Alert Analysis

Overview

This project demonstrates the investigation and validation of Suricata Intrusion Detection System (IDS) alerts using packet-level analysis in Wireshark. A network traffic capture (PCAP) was analyzed to determine whether the generated alerts represented legitimate security events or false positives.

The investigation focused on two high-priority Suricata alerts associated with the LandUpdate808 exploit kit. By correlating IDS alerts with DNS queries, DNS responses, and TLS handshake data, the investigation confirmed the alerts as True Positives.


Objectives

  • Configure and use Suricata to analyze a PCAP file.
  • Investigate IDS alerts generated during traffic analysis.
  • Validate Suricata detections using Wireshark.
  • Identify Indicators of Compromise (IOCs).
  • Produce a professional incident report documenting the investigation.

Tools Used

  • Suricata
  • Wireshark
  • Kali Linux
  • macOS
  • Git & GitHub

Skills Demonstrated

  • Intrusion Detection System (IDS) Analysis
  • Network Traffic Analysis
  • DNS Investigation
  • TLS Handshake Analysis
  • Packet Capture (PCAP) Analysis
  • Alert Validation
  • Indicator of Compromise (IOC) Identification
  • Incident Documentation

Investigation Summary

The investigation identified suspicious communication between an internal host and the domain hillcoweb.com. Analysis confirmed the following sequence of events:

  1. Suricata detected a suspicious DNS lookup.
  2. Wireshark confirmed the DNS query from the internal host.
  3. The DNS server resolved the domain to an external IP address.
  4. The endpoint initiated an HTTPS connection.
  5. TLS analysis confirmed the Server Name Indication (SNI) contained hillcoweb.com.
  6. Both Suricata alerts were validated as True Positives.

Key Findings

Finding Result
Internal Host 10.6.13.133
Suspicious Domain hillcoweb.com
External IP 67.217.228.199
Classification True Positive
Confidence High

Repository Structure

Suricata-Alert-Analysis/
│
├── README.md
├── Incident-Report.md
├── IOC-List.md
├── Screenshots/
│   ├── 01-fast-log.png
│   ├── 02-dns-query.png
│   ├── 03-dns-response.png
│   ├── 04-tls-sni.png
│   └── 05-alert-summary.png
└── LICENSE

Screenshots

Suricata Alert Summary

Suricata Alert Summary


DNS Investigation

DNS Query

DNS Response


TLS Investigation

TLS SNI Investigation


Documentation


Lessons Learned

This project reinforced the importance of validating automated IDS detections with packet-level evidence. By correlating Suricata alerts with Wireshark analysis, I developed practical experience in alert triage, network traffic analysis, IOC identification, and professional incident documentation.


Disclaimer

This project was completed in a controlled lab environment using publicly available traffic captures for educational purposes.

About

SOC investigation using Suricata IDS and Wireshark to validate alerts, identify IOCs, and document incident response findings.

Topics

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors